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iPhone target analysis and exploitation with unique 

device identifiers 



This paper describes standard analysis techniques 
that have been used to both discover iPhone 
target end point machines and implant target 
iPhones directly using the QUANTUM system. It 
shows that the iPhone Unique Device Identifier 
(UDID) can be used for target tracking and can be 
used to correlate with end point machines and 
target phone. It highlights the exploits currently 
available and the CNE process to enable further 
targeting. 
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B. BACKGROUND 

1. Every Apple iPhone, iPad and iPod touch has a unique hardware 
identifier called the Apple UDID. The UDID is a 40 character hex string 
(160 bits) that seems to be a SHA-1 hash of the IMEI, serial number and 
the Bluetooth and WiFi MAC addresses. The UDID is available to 
developers of applications for these devices, and it is used to identify a 
given device. As highlighted in [a], the UDID is seen in multiple apps and 
can be used to allow target tracking or be used to correlate with other 
personal identifiers. 

2. The Mobile Theme has invested a large amount of research into iPhone 
apps and metadata analysi^ver the last year accumulating with a 
detailed report done by^^|[c] in October 2009 and 29 SEM rules 
created by ICTR-MCT [b]. These rules have used to extract iPhone 
metadata for a number of apps and in particular the Unique Device 
Identifier (UDID) from any carrier being processed using DEBIT CARDS. 
Further TDI rules are being developed by GTE that will in the future 
extract UDID events from carriers processed through the MVR system. 
The resulting events have then been used to populate both research and 
corporate QFDs (Query Focused Datasets) such as MUTANT BROTH 
and AUTOASSOC and will eventually form the basis of mobile 
correlations in HARD ASSOC. 

3. Initially, an exploit was developed by the Joint CNE/TECA Mobile 
Exploitation Team for iPhone that was to be delivered to the target 
phone when syncing with an exploited end point machine. This was 
successful for a BROKER target and resulted in the extraction of SMS, 
call logs and contact details. After this initial trial, CNE and SD undertook 
work to discover other single end points seen syncing with iPhones. 

4. At HANDEX 2010 (handset exploitation workshop) in August, various 
aspects of the iPhone OS were investigated for potential vulnerabilities. 
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Using an open source PDF vulnerability when using the Safari browser, 
Joint CNE/TECA Mobile Exploitation Team were able to develop an 
exploit to deliver a WARRIORPRIDE implant to a target test phone. 
Further, investigation, liaison and testing with the CNE QUANTUM team 
resulted in approval for the implant to be deployed against QUANTUM 
iPhone targets. 



C. DESCRIPTION OF ANALYSIS 

CNE Endpoint 

5. As part of the SD Mobile Exploitation theme to identify further end point 
machines that had been seen syncing with iPhones, a survey was 
undertaken by CNE and TAO to scan all target end point machines for 
the appropriate iPhone registry keys. Scanning of all CNE stored single 
end point (SEPs) registry keys on particular process IDs resulted in 9 
CNE endpoints seen this year sync’d with iPhones. The resulting Unique 
Device Identifiers (UDID) were extracted from the registry keys and ran 
in MUTANT BROTH and AUTOASSOC, resulting in 6 correlations with 
either iPhone Safari user agents or the iPhone Mail app seen in passive 
collection. 

6. ACNE end point operation against ^^^^^^^KaBSOLINE 
EPI^ON^^d resulted in access to a windows end point machine 
^^^^^^R^^car^nhi^TTachinej^^agistr^ resulted in UDID 

As be the 

UDID has been seen with the Admob SEM rule type and with the Apple- 
IMEI-URI TDI type. Admob is the largest mobile advertising network 
allowing games publishers to embed adverts and therefore receive 
revenue from a number of different brands. The target iPhone OS is 3_0 
as shown in the User Agent profile in figure 2. 



TDI type TDI value 

0 EWP_Admoli-isu-URl 

EAUTO_ApplB-imei-URI 
EXP_Admob-X-Admob-Isu 

Figure 1 - MUTANT BROTH Matching Identifiers 

TD! User-Agent 




Event Count 
( 9 &) 



Mozilla/5.0 (iPhone; U; CPU iPhone OS 3_0 like Mac QS X; HW iPhonel»2; en-u«) AppleWebKit/525,18.1 3 (18 %) 

(KHTML, like Gecko) (AdMob-ISDK-20090203) 

iPhone Mail (7A341) 11(63%) 

Mozilla/5.0 (iPhone; U; CPU IPhone OS 3_0 like Mac 05 X; ttw iPhoneUZ; en_us) AppleWebKit/SZS.LO.l 2 (12 %) 

(KHTML, like Gecko) (AdMob-iSDK 20090609) 



Figure 2 




iPhone UDID User agent profile 
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7 . 



The target UDID can be used track the iPhone seen with ASBOLINE 
EPILSON end point machine. In this particulai^as^h^ai^^ has 
been seen 16 times, the last time off on the 

24/10/10 using the inbuilt iPhone Mail client to access his yahoo 
account. The user agent for this is shown in Figure 3. In this case the 
EAUTO_Apple-imei-URI TDI rule was used to extract the specific UDID 
value. 



TDI-Scope Auto Route 
User-Agent iPhone Mail (7A341) 
Ldbelled-Ro ute 



Figure 3 - iPhone Mail client user agent 



Bearer Sigad Pddg Ssdg Other Info 



8 . 



GWVCBOOl 



TPl-Scope Ma chine Route 
■■■■■source CPC.DEBITCARD 
Format-Transform SEM->TDI 
User-Agent Mozilla/5.0 (iPhone; U; CPU 
iPhone OS 3_0 like Mac OS X; HW 
iPhonelj2; en_us) AppleWebKit/525.18.1 
(KHTML, like Gecko) (AdMob- 
iSDK-20090609) AS-IP-Src NO_MATCH 



Figure 4 - iPhone Admob user agent profile 



The UDID for a ll 6 targets were run through AUTOASSOC. The result for 
is s hown in Figure 5. As can be seen there is a clear 
correlation with the yahoo-Y-cookie. 



Known TI>1 



EXP_Admob-isu-URI: 



EXP Admob- X- Admob- Isu: 



Put<3tive TDI 



Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 

Yahoo-Y -Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 
Yahoo-Y-Cookie: 

EXP Admob-X-Admob-Isu. 




EXP_Admob -isu- URI: 



CORINTH 

tasking? 



Score Events 



1.000 13 

0.500 1 

O.SOO 1 

0.500 1 

0.500 1 

0.500 1 

0.500 1 

0.500 1 

0.500 1 

O.SOO 1 

0.500 1 

0.500 1 

0.500 1 



Figure 5 - AUTOASSOC results for ABSOLINE EPSILON 

9. The IP address, identifier type, bearer and user agent type for all 6 

targets was extracted and formed the basis of further target development 
work. Running the resulting 6 UDIDs through AUTOAS SOC, resulted in 
two correlations with a high enough score. These were 
and and confirmed to be correct after discussing with 



Most 

recent 

24/10/10 

23/00/10 

14/11/09 

14/11/09 

19/06/10 

10/12/09 

19/08/10 

23/00/10 

10/12/09 

19/06/10 

15/11/09 

19/09/10 

19/09/10 
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Checking BROADOAK tasking revealed that both targets 
had known associated iPhone IMEIs already tasked. 

10. A recent rescan of all currently active CNE SEPs resulted in only 5 of the 
9 identified CNE machines actually being available for exploit. The other 
4 implants having been removed. Of these five UDIDs, four returned with 
correlated UDIDs that had recently been seen in passive collection. 
These are contained in the iPhone target list [f]. 

11. Analysis of all TAO SEPs resulted in 116 UDIDs being identified. Of 
these UDIDs, 15 were correlated with iPhone user agents and the 
resulting identifier type, project name, case notation and IP noted. A full 
list is available in the iPhone target list [f]. Of these four had the Cydia 
user agent as shown in Figure 6 indicatin g the targ et had jailbroken their 
phone. All four end points were located in^^^^|. 



TPl-Scnpe Ma chine Route 

Source CPC.DEBITCARD 
Format-Transform SEM->TDI 
User-Agent Mozilla/5 .0 RockApp/2.60.1 
(iPhone: u; CPU like Cydie/l. 0.3172-68) 
AppleWebKit/518.10 (KUTML, like Gecko) 
y ers ion/4 .0 Mobile/7Dll Safa ri/528.1 6 
AS-]P-Src AS-IP-Ost^^l 

Labelled-Route 




EF07C80000000000000000000000000020 



Figure 6 - iPhone jailbroken user agent in MUTANT BROTH 

12. The same 15 TAO UDIDs were run through AUT OASSOC and resulted 

inthreegoodco^ y ahoo selectors 

and 

turn confirmed to be correct correlations with TAO target end points and 
two showed associated target iPhone IMEIs. Further, analysis of the 
Yahoo mail used via the Safari browser clearly showed the resulting 
UDID was transmitted in traffic. 

13. One of these TAO end point machines, SOLARSHOCK116 
^^^^^^^^^^^^^^Ji^nian)Jia^eer^eei^vr^ng with iPhone 

was 

with ng 

A^TOASSOCJt^UDID was last seen on 23/10/10 at 03:46:36z on 

using the EAUTO_Apple-imei-URI TDI. 






Arf»fnAS to; 




ra5;yri5.> 



Most 

recerr 



i.nno 33 ?vin/in 

1 OOCi 7$/n\/Ut 

0.636 2 2fl/01/10 

0.500 1 20/06/10 

o.sno 1 ?vn6/io 

O.SUO 1 20/VdAi'i 

0.500 1 21/10/10 

o.sofi 1 ?vofi/irt 



C>4Kml 



n 

[d 

El 



El 



C3 

El 

0 



Figure 7- SOLARSHOCK116 UDID AUTOASSOC correlations 
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QUANTUM EXPLOIT 

14. After extensive testing of the QUANTUM tipping and redirection to the 
SHORTSHEET exploitation server by the Joint CNE/TECA Mobile 
Exploitation Team, further target development work was needed to 
identify iPhone targets recently seen active on the appropriate user 
agents. Bulk extraction of targets over a three-week period from 
BLACKHOLE by ICTR resulted in a large number of iPhone targets and 
further queries in Xkeyscore resulted in others. Others were passed from 
discussions with various IPTs and two were also passed from TAO 
contacts. 

15. In total 44 selectors were checked to verify that the correct user agent 
was present. Of these 44 selectors, 41 were yahoo selectors and 3 gmail 
selectors. Of these 26 were seen with a valid iPhone Safari user agent 
as shown in Figure 8. A summary of OS versions seen with target 
phones is shown in Table 1 with OS highlighted in red currently 
exploited. These are 3_1_2, 3_1_3 and 4_0_1. In all 26 cases, the target 
analysts were contacted with details regarding their targets use of an 
exploitable iPhone. 



iPhone OS 


Number 


3_0 


4 


3_1 


2 


3_1_2 


6 


3_1_3 


15 


4_0 


3 


4_0_1 


5 


4_0_2 


1 



Table 1 - iPhone target OS summary 

24. One par ticular case was target, with yahoo 

selector ^^^^^^^^^^|th^was seen active on a iPhone OS 
3_1_2, as shown in Figure 8. The resulting Yahoo-B cookie is 
^^^^^^^■an^^ai^^eei^h^arget has been active off 

Running the Yahoo- 

B cookie through MUTANT BROTH resulted in 171 events primarily on 
case notations GWUKG005, GWVCB003 and IRUKC036. The resulting 
information was then forwarded to the analysts in the^^^|team for 
tasking by the standard ONE process as outlined in the Good 
Penetration Guide [d]. 
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fSourcc CPC_DEBnCARD Format-Tran%fi 

j^jy^-Agent MD:illa/5,C (iPhone; U; CPU iPhone OS 3_1_2 like M ac QS X; en-us) 

111 r.ii II 1 1 H e.c-10-n^t i 



>TDI Yahoo-B-Cookic^^^^^^^^l Yahoo-Y- Cookie 
f&Webi<iV528.l9 (KHTML,Tl<^GecKo^?^si on/4.0 Mobile/7Dll 
lEvent-CSi EF07C6 Stream-CSL EF07C9 



TDI^S^pe Machine Route Source CPC_DEBITCARD Format-Transform SEM->TDI YahoD-B-Cookie^^^^^^^^|Yahoo-Y-Cookie 
Agent Mojilla/5,0 (iPhone; U; CPU tPhone OS 3_1_2 like M ac OS X; en-us) AppleWebKrt/528.1S (KHTML, lik^Gedco^?e^ion/4.0 Mobile/7DLl 
SaFan/52B.16 AS-lP-Src NO MATCH AS-lP-Dst Labelled-Route Event- CSL EF07C6 Stream-CSL EF07CS 



TDI-Scope Machine Route Agent Mo^illa/ S.D (iPho ne; U; CPU iPhcn e OS 3 1 2 like M ac OS X; en-us) AppleWebKit/523.L8 (KHTML, like 

Gecko) Version/4.0 Mobile/7Dll Safen/528.L6 Yahoo-Y- Coo kle Yahoo-B-Cookie^^^H^^|Yahoo-T-Cookie 

2-59mjMB5RO0MBZVB0SvGskx/M2l2BjY3NjU2M2ROM0e-B<a-rAE&sk-DAAYIXEBDZnNKU&kj-EAAhNKFiJQutIRDCfXj7neYag E& 

d»c2wBTkRVMEFUBXdNVEldTkRNNU5EZyQBYQFZQUUBZwFFMTdKTlpXMlFNSExGQTdQUORORlBGQUg2TQFwawFaVzAtAXp6ATU5bWpNQkE3RQFDaXABQlI4V]ND& 
af=QXdBQjFOJnR2PTE¥OOQOMDMwNjUmcHM9UVRkY>!F2WUtWai54LlUZLlWndmZI9JZyOt Yahoo- V- Cookie-Full v=l&n=abqik0qdwtkfn&I=c0jj948/o& 
P=m2nnoooooi30oaoooe(r'=89ftlg=en-usetintl*us8inp=i Event-security-label iooo 7F stream-security-label 4aoo23EOFF 

TOI-Scope Usar Route^^^^^^^Buser-Agent Mo;illa/5.Q (iPhone; U; CPU iPhone Q S 3_1_2 like Mac OS X; en-gy) AppleWebKit/528.18 (KHTML, like 
Gecko) VersiaiV4.0 Mcbile/7Dii sefari/529.16 Yahoo-Y-Cookie^^^H Yahoo-B-Cookie^^^^^^^^Hvahoo-T-Cookie 
^•CQmiMnCD noMa7UBn.;%f<^eLv7MT.T:»R.Y'^Will7MT.B(nMnin.fl.*»VAPfceL-n4AVTvCn.rt'7r.Ml'im,L-c; jF7nPrRCTJWrffDnrfV.7r.7^Mj»n Pft. 



Figure 8 -Valid iPhone Safari user agent in MB ( 




yahoo>) 



25. 



The target wi th target selector 

was seen active on different iPhone OS 
and more recently on an iPad. Three other targets were seen active on 
iPads and two others on iPods but with no other associated iPhone 
device. Of the 44 targets seen, 16 were seen using the iPhone Mail 
client that comes by default with all OS. A total of 7 targets were seen 
using the Yahoo Mobile Messenger app. 



26. For all target selectors seen with valid Safari user-agents, further 

MUTANT BROTH, AUTOASSOC and MARINA queries were performed 
to discover any other possible OS versions seen with the selector. 
MARINA profile queries were performed resulting in the OS version 
being returned within the MachinelD field. The resulting user-agents, 
time/date, bearer, IP and any other associated selectors are shown in 
the iPhone target list [f]. Associated selectors are either from MUTANT 
BROTH, AUTOASSOC or seen directly as stated in BROADOAK. All 
Yahoo B-cookies as shown in Figure 8 were run in MUTANT BROTH to 
confirm their uniqueness with the iPhone and target yahoo selectors. 



D. OPERATIONAL OUTCOME 



27. The QUANTUM redirect and PDF Safari browser exploit was developed 
to work against 3_1_2, 3_1_3 and 4_0_1 Safari OS versions. Of the 26 
targets seen with valid exploitable OS version, 5 were added to the 
QUANTUM system for targetting. 



28. 



29. 



Once notified, GCHQ IPTs either added the target to existing ONE 
section 7 warrants as defined in [e] or developed targetting aids as 
defined in [d] and wrote the appropriate warrant. The resulting section 7 
warrants were approved by IPT team leaders and signed off by the ONE 
Legal Team. Three NSA targets were discovered and were added by 
ONE Legal Team to the Partner Agreement Forms to allow exploitation. 




Initially, 



and B- 
was not seen 



yahoo selector 

cookie was put on cover on QUANTUM.] 
active recently on a iPhone Safari browser to access his yahoo account, 
preferring instead to use the inbuilt iPhone Mail client or his iPad. Three 
QUANTUM attempts resulted in no redirect to SHORTSHEET server for 
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^^■and after further analysis it was discovered that this selector was 
not^^Hbut an associate. It was removed from tasking. 

30. Target analysis and warrant was completed for a further five targets and 
a successful Q UANTUM redirect and the PDF exploit was delivered for 

PFVT658) on the 30th of October. The resulting 
WARRIORPRIDE install was also performed and beaconed on the 2"^^ of 
November. The target phone was shown to be jailbroken and on the 3'^'' 
of November content was successfully extracted from the phone and 
was available in Looking Glass. This is highlighted in Appendix B with 
the resulting iPhone directory structure presented how it appears in 
Looking Glass. The WARRIORPRIDE exploit has resulted in extraction 
of the target’s address book, sms, call logs, notes, WLAN logs, 
bookmarks, map query history. Safari browsing history and some 
images. Detailed analysis of extracted files will be covered in a further 
report. 

31. A successful redirect to in October was 

performed but due to what is believed to be Javascript being disabled on 
the phone the firmware type of the phone could not be confirmed to 
enable the first stage implant. This initial survey of the firmware type has 
now been removed after discussions within ONE but the target has not 
been seen recently on his iPhone for exploitation. The two other targets 
tasked for QUANTUM have failed to be seen recently in collect. 

32. Currently, there are four CNE Single End Point machines that have been 
identified with recently sync’d iPhone targets. The most recent being an 
OVERLIT target seen on 29/09/10. These targets are being monitored 
by CNE and will have the SLIDE exploit installed to allow implant of 
WARRIORPRIDE when the iPhone is sync’d with the existing SEP 
machine. 

E. CONCLUSION 

33. With the analysis of the UDIDs on target machines and correlation in 
passive collection with known target yahoo selectors, the UDID can be 
used to correlate iPhone handset to end point sync machine and tasked 
yahoo selectors. The UDID can be used for realtime tracking of target 
iPhones and could in theory be used as a selector for QUANTUM events 
where other traditional selectors (yahoo- Y/B cookie etc) are not present. 
Of course an exploit for the application would have to be written which is 
not trivial. 

34. It is not possible at this time to take the UDID and reverse engineer the 
SHA-1 HASH to discover the IMEI, MAC addresses and serial number. 

35. Further work is ongoing to identify targets of interest that are suitable for 
the QUANTUM exploitation. Development and monitoring of current 
identifiedtar^^ is still being done. Discovery of an associated IMEI for 

will help in firmware identification and exploitation of this 

target. 
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36. CNE are now conducting monthly surveys of all target machines registry 
keys for iPhone UDIDs. A similar tipping mechanism for all BROADOAK 
hits needs to be completed using a XKS workflow. Hopefully, other 
targets will be added for QUANTUM exploitation or discovered on new 
CNE SEPs in the future and a successful exploit of a target phone 
performed. 

F. FURTHER WORK 



37. Analysis of three PRESTON accesses has resulted in the identification 
of a number of iPhone targets. Development work against at least three 
target sets is needed with extraction of appropriate UDIDs and iTunes 
XDSID values. Suitable section 5 warrants need to be in place to pursue 
these end point machines, once CNE have gained access and the 
resulting target iPhones have been discovered. 

38. With further work being undertaken by BSS and TECA on the 
WHIPSAW redirect and exploitation server, it should be possible in the 
coming months to implant directly the target iPhone. However, the 
WHIPSAW exploit is only available via the tasked ADSL line. 

39. An automatic implantation of SLIDE on to an iPhone is needed. 

Currently this is manual process requiring a CNE operator to be 
connected to the endpoint machine whilst the target is syncing the end 
point machine and iPhone. 

40. A larger number of iPhone TDIs need to be written to allow further 
events to be populated into the QFDs allowing correlations with other 
target selectors. This will also enable further real-time tracking of target 
identifiers. 
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APPENDIX B 



Looking Glass iPhone directory structure 



\lib'ary\preference;\systenconfigLration 



m /va7mobile^mediQ/dcim^lO0Qpple/i[Tig_041C.jpc 
(D /var/mobile^media/dcim^l00apple/iting_041?.jpc 

R-St 

l^bin 
^ dev 

; 0 ^ library 

0 ^ pre-erences 

sys:emconfiguration 

: 0 private 
cb vor 
S ^ sys:em 
R & library 

0 ^ appleptp 
0 1^ appleufbdevice 
0 ^ aucio 
0 caoes 

0 carrier bundles 

0 coreseivices 

(i) dataclassmigrators 

9 extansisns 

R ^ Filp^ycl-amc 
0 & fon:s 
0 & frameworks 
0 & internet plug-in; 

0 & keyboa-ddictionaries 
0 & iaunchcaeraons 
0 & iockdown 

9 ^ monQgedconfigjrakonbundes 
9 ^ mediacaptcre 

9&prfi=firpnrfthiindift^ 

0 ^ privatefrarreworks 
0 ^ putlishhgbundbs 
9 ^ searchbuncles 
0^sprhgb3ardplugins 
li & sysremcontiguration 
©fe'texrinput 
9 videodecodei's 

9 ^ vidaoancoders 

0'(^iKr 

bin 
^ sbin 
0 ’(& var 

^ mobile 






ccm, apple, auto wake, plist 
|| ccm, apple, n0twoik,identiticaton,pli£t 
|| rrm. apple. wif.pikf 
l| netwcrkin:erfaces,plist 
|| prefetenc3s,plist 



I I 

IQ 

L 

L ^ 



004, OD 
20,22KE 
IR.nilfF 
1,35KB 
16,:6KE 



PLI3T File 
PI T5T Filfi 



Path 

,, \libiar/\pi:feiences\,,, 
,, \librarv\praFeiences\,,, 
.. \lihrarv\pr=ffiiiRnrfic\... 
,, \librarv\pr3feiences\,,, 
,, \librarv\pr3ferences\,,. 



returned files 




Date MuJiFied 
01 -Jan-1000 00: „, 
03-NOV-201017,,, 
n3-Nr>v-;nini7... 
01 -Jan-1300 00: „, 
03-NOV-201017,,, 



1 ^ 



File Searcher 



» Set Sedu.1 Pdiciiieters 



’-MsdficatiDn time ' 

1 deFajIt |n| 


-Creadon time » 

1 defaut: [yj 


-accessed dm? ' 

1 defaJt: [v| 


?.e:rieved \ 

□ |o€iai v| 


alter 1 11111/2000 gj 


after 1 11/1 U2000 g| 


after |ll/ll,'2C0C g| 


oPber Ilijnm ^j| 


nt>Fn |l1l1/7nin g 


lip -n |il/ ij?nin g| 


iipfn |n/ii;?nr g| 


ipfn|ll/l!.'?ir^n,.i 1 


-FiB5ke(iiKB; 


-Tcil i 1 dll/paiL uf fileiiaiiie; 






1 1 


1 Search] 


mh| 0| 


Specify Path; 


is JO Fiie(s) Found 


max 1 00071 992547409? 1 | 


r 1 





Vn'orning; Mo>amum scorch 
rssult reached (000), 

Try a mo e sp:ci3c search 



Mailt 


1 1 1 




Fiie Type 


Fall 


Ddlt MudfitU 




Dale CedleU LiiikTa yel 


Staljs 


Dale RiBLeived 


S cdcre;sbook,;gltedb 


d 7 


236.0KB 




... \\oriyate\va'\mobile\... 


Jl-Jcn-180000 




Jl-Jan-18J00C;... 


RECEIVED 


02/11/10 13;0£ 


|§ edcressbook,sqitedb 


d 7 


200.0KD 




... \Frivote\\•or^m3bieVi... 


Jl-Jen-1000 00 




Jl-Jan-lOJOOC;... 


RCCCIVID 


02/11/10 16:0C 


0 sm£,dD 


d 


88.0KB 




... Uoriyatelva'linobiiel... 


Jl-Jcn-180000 




Jl-Jan-18J00C;... 


RECEIVED 


OZfUllO 13:06 


1 l^sms.ds ■ 




88.0KB 




... \p1v«bt\vwvinblliii|i|lf-Jan-lBOOOO 






J[bFrFiv-n 1 


1 DSj/ll/lO 16;3£ 


0 ujiii,<4jpc,.uiiiiiLe itBr,ptbl 


d ^ 


134 ,0b 




,,, \\ra'\iiiubiiBdiLra'y\,,, 


Jl-Jci 1-1600 00 




Jl-Jdi I-18J0 OC;... 


RECEIVED 


02/11/10 t3:0£ 


0 oonn,appe,:om[rceTter,plist 


d 7 


134. OB 




... \vartmoble\ibtary\p.. 


Jl-Jcn-180000 




Jl-Jan-18J00C;... 


RECEIVED 


02/11/10 16;3£ 


0 com, appe, wifi, plist 


E 7 


14.9KB 




... \\ibiarv\pre=eierces... 
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